• No results found

PIN B.) userid

In document TK-CISSP.v39.1_1451q_ (Page 128-133)

Section 2, Data Access Controls (68 Questions)

QUESTION NO: 2 What is Kerberos?

A.) PIN B.) userid

C.) password D.) challenge

Answer: A

QUESTION NO: 13

How are memory cards and smart cards different?

A.) Memory cards normally hold more memory than smart cards

B.) Smart cards provide a two-factor authentication whereas memory cards don't C.) Memory cards have no processing power

D.) Only smart cards can be used for ATM cards

Answer: C

"The main difference between memory cards and smart cards is the processing power. A memory card holds information, but does not process information. A smart card has the necessary hardware and logic to actually process information." Pg 121 Shon Harris CISSP All-In-One Exam Guide

QUESTION NO: 14

They in form of credit card-size memory cards or smart cards, or those resembling small calculators, are used to supply static and dynamic passwords are called:

A.) Tickets B.) Tokens

C.) Token passing networks D.) Coupons

Answer: B

QUESTION NO: 15

Tokens, as a way to identify users are subject to what type of error?

A. Token error B. Decrypt error C. Human error D. Encrypt error Answer: C Explanation:

Tokens are a fantastic way of ensuring the identity of a user. However, you must remember that no system is immune to "human error". If the token is lost with it's pin written on it, or if it were loaned with the corresponding pin it would allow for masquerading. This is one of the greatest threats that you have with tokens.

QUESTION NO: 16

Which of the following factors may render a token based solution unusable?

A. Token length B. Card size C. Battery lifespan D. None of the choices.

Answer: C Explanation:

Another limitation of some of the tokens is their battery lifespan. For example, in the case of SecurID you have a token that has a battery that will last from 1 to 3 years depending on the type of token you acquired. Some token companies such as Cryptocard have introduced tokens that have a small battery compartment allowing you to change the

battery when it is discharged.

QUESTION NO: 17

Memory only cards work based on:

A. Something you have.

B. Something you know.

C. None of the choices.

D. Something you know and something you have.

Answer: D Explanation:

Memory Only Card - This type of card is the most common card. It has a magnetic stripe on the back. These cards can offer two-factor authentication, the card itself

(something you have) and the PIN (something you know). Everyone is familiar with the use of an ATM (Automated Teller Machine) card. These memory cards are very easy to counterfeit. There was a case in Montreal where a storeowner would swipe the card through for the transaction; he would then swipe it through a card reader to get a copy, while a small hidden camera was registering the PIN as the user was punching it on the pad. This scheme was quickly identified as the victims had one point in common;

they all visited the same store.

QUESTION NO: 18

Which of the following is a disadvantage of a memory only card?

A. High cost to develop.

B. High cost to operate.

C. Physically infeasible.

D. Easy to counterfeit.

Answer: D Explanation:

Memory Only Card - This type of card is the most common card. It has a magnetic stripe on the back. These cards can offer two-factor authentication, the card itself

(something you have) and the PIN (something you know). Everyone is familiar with the use of an ATM (Automated Teller Machine) card. These memory cards are very easy to

counterfeit. There was a case in Montreal where a storeowner would swipe the card through for the transaction; he would then swipe it through a card reader to get a copy, while a small hidden camera was registering the PIN as the user was punching it on the pad. This scheme was quickly identified as the victims had one point in common;

they all visited the same store.

QUESTION NO: 19

The word "smart card" has meanings of:

A. Personal identity token containing IC-s.

B. Processor IC card.

C. IC card with ISO 7816 interface.

D. All of the choices.

Answer: D Explanation:

The word "smart card" has four different meanings (in order of usage frequency):

IC card with ISO 7816 interface Processor IC card

Personal identity token containing IC-s

Integrated Circuit(s) Card is ad ID-1 type (specified in ISO 7810) card, into which has been inserted one or more integrated circuits. [ISO 7816]

QUESTION NO: 20

Processor card contains which of the following components?

A. Memory and hard drive.

B. Memory and flash.

C. Memory and processor.

D. Cache and processor.

Answer: C Explanation:

Processor cards contain memory and a processor. They have remarkable data processing capabilities. Very often the data processing power is used to encrypt/decrypt data, which makes this type of card a very unique personal identification token. Data

processing also permits dynamic storage management, which enables the realization of flexible multifunctional cards.

QUESTION NO: 21

Which of the following offers advantages such as the ability to use stronger passwords, easier password administration, and faster resource access?

A.) Smart cards

B.) Single Sign-on (SSO) C.) Kerberos

D.) Public Key Infrastructure (PKI) Answer: B

QUESTION NO: 22

What is the main concern with single sign-on?

A.) Maximum unauthorized access would be possible if a password is disclosed B.) The security administrator's workload would increase

C.) The users' password would be to hard to remember D.) User access rights would be increased

Answer: A

QUESTION NO: 23

Which of the following describes the major disadvantage of many SSO implementations?

A.) Once a user obtains access to the system through the initial log-on they can freely roam the network resources without any restrictions

B.) The initial logon process is cumbersome to discourage potential intruders

C.) Once a user obtains access to the system through the initial log-on, they only need to logon to some applications.

D.) Once a user obtains access to the system through the initial log-on, he has to logout from all other systems

Answer: A

Reference: "The major disadvantage of many SSO implementations is that once a user obtains access to the system through the initial logon, the user can freely roam the network resources without any restrictions." pg 53 Krutz: CISSP Prep Guide: Gold Edition

QUESTION NO: 24

Which of the following addresses cumbersome situations where users need to log on multiple times to access different resources?

A.) Single Sign-On (SSO) systems B.) Dual Sign-On (DSO) systems C.) Double Sign-On (DS0) systems D.) Triple Sign-On (TSO) systems

Answer: A

QUESTION NO: 25

A method for a user to identify and present credentials only once to a system is known as:

A. SEC

In document TK-CISSP.v39.1_1451q_ (Page 128-133)